The invention relates to the technical field of intrusion detection, in particular to a network
threat detection method and
system, and the method comprises the following steps: building a
threat path logic diagram through collecting field dependency items, action trigger
timestamp items and action propagation hop count items of an
attack behavior chain, and matching field dependency items among nodes based on a
graph theory algorithm to obtain a
threat path logic diagram; and detecting a
mutual exclusion logic field combination, and generating a logic diagram structure with a connecting edge and a
mutual exclusion mark. In the method, a threat path logic diagram is constructed by fusing field dependence, action timestamps and propagation hops,
graph theory identification field
mutual exclusion combination enhances cross-protocol
attack chain analysis, and hidden Markov modeling
state transition probability verifies
time sequence continuity and
path length. And performing
dynamic time warping alignment on forward and reverse instruction sequences to extract semantic offset, overlapping rate and
time sequence entropy, and performing non-linear
score classification based on an isolated forest to detect an adversarial sample, topological
structure analysis,
time sequence verification, instruction alignment and non-linear classification to cooperatively identify a composite
attack with field mutual exclusion and time sequence
confusion.